Viewing profile — tsteenbe
tsteenbe
HN member- Joined
- Mon, Jan 06, 2020, 10:48 AM UTC
- HN karma
- 45
- Public activity
- 7 items
- HN profile
- View on Hacker News ↗
About tsteenbe
Recent public activity
-
comment
Comment #43087333
This is why several German automotive OSPOs are working together to build OSS Review Toolkit (ORT) - it kinda glues various open source tools like ScanCode but adds features like t…
-
comment
Comment #32123456
> Do HN got a recommendation for other CLI based SBOM generators? Try ORT https://github.com/oss-review-toolkit/ort (full disclosure I am one of its maintainers and also the lead o…
-
comment
Comment #26790102
Good catch I missed that openCVE is Business Source License which I actually do not consider to be open source.
-
comment
Comment #26789945
Are you aware of https://github.com/nexB/vulnerablecode ? which offers a similar solution, is also open source and written in Python.
-
comment
Comment #21968584
> It makes license scanning a doddle. As someone working in the field of license compliance (leading an Open Source Program Office) and dealing with the licensing of tens of thousa…
-
comment
Comment #21968406
> A trivial solution would be to create a crowd-sourced dependency vetting platform. Such a platform is already being developed by various organizations, see https://clearlydefined…
-
comment
Comment #21968296
If you want to do license compliance for various package managers then I recommend you checkout https://github.com/heremaps/oss-review-toolkit . Full disclosure: I am one of the ma…